Cross-Site Scripting Vulnerabilities in Ubercart Module for Drupal
CVE-2008-1428

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
20 March 2008

Summary

The Ubercart module for Drupal has multiple vulnerabilities that allow attackers to execute arbitrary scripts by injecting malicious content into product attribute values. This could lead to unauthorized access, data theft, or manipulation of user sessions, putting affected sites at significant risk. It's crucial for users of the Ubercart module to update to the latest version to mitigate these security flaws.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.